While waiting for Docker Sandbox to catch up with Pi, I started this project: https://github.com/shaftoe/sbx-template-pi
TL;DR: `sbx run --kit "git+https://github.com/shaftoe/sbx-template-pi.git#dir=sbx-kit" sbx-template-pi` to run Pi in a Docker sandbox with up-to-date Pi.